Port 25: Simple Mail Transfer Protocol
Port 25 is the standard port for the Simple Mail Transfer Protocol (SMTP), which RFC 5321 notes is specified by IANA as port 25. Mail servers use it to relay messages to one another, usually after finding the receiving server through DNS MX records. Mail submission by user clients belongs on port 587 or 465 instead (RFC 8314).
Port Details
Security Exposure
A server that relays mail for anyone becomes an open relay that spammers abuse, and RFC 2505 states that an MTA must be able to restrict unauthorized use as a mail relay. SMTP on port 25 starts in cleartext unless STARTTLS is negotiated. RFC 8314 says providers that still accept cleartext SMTP on port 25 for user message submission should move users to TLS.
Hardening
- +Restrict relaying to authenticated users and the domains the server is responsible for (RFC 2505).
- +Offer STARTTLS (RFC 3207) on port 25 so server-to-server traffic can be encrypted.
- +Move client submission to port 587 with STARTTLS or port 465 with implicit TLS, as RFC 8314 recommends.
- +Keep mail transfer agent software patched and enable logging of anti-relay and anti-spam rejections.
Monitoring
Log relay denials, SMTP AUTH failures, and sudden growth in outbound mail volume. RFC 2505 recommends that MTAs be able to log all anti-relay and anti-spam actions.
SMTP Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability | - | 9.8 | 71.7% | KEV | 2010-12-14 |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability | - | 7.8 | 18.0% | KEV | 2010-12-14 |
| CVE-2019-16928 | Exim Out-of-bounds Write Vulnerability | - | 9.8 | 41.6% | KEV | 2019-09-27 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | exim | 9.0 | 100.0% | KEV | 2019-06-05 |
| CVE-2018-6789 | Exim Buffer Overflow Vulnerability | - | 9.8 | 82.1% | KEV | 2018-02-08 |
Tools for Auditing and Monitoring SMTP
Rspamd
Free / CommercialFast open source spam and phishing filtering system for Postfix, Exim, and Sendmail.
Apache SpamAssassin
Open SourceClassic open source spam filter using heuristic scoring, Bayesian classification, and a plugin architecture.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
What is the difference between ports 25, 587, and 465?→
Port 25 carries SMTP relay between mail servers. For client message submission, RFC 8314 says clients and servers should implement both STARTTLS on port 587 and implicit TLS on port 465.
Is SMTP on port 25 encrypted?→
Not by default. The session starts in cleartext and can be upgraded with the STARTTLS extension defined in RFC 3207.
What is an open relay?→
An open relay is a mail server that forwards mail for any sender to any destination without authorization. RFC 2505 requires MTAs to be able to restrict this because spammers use open relays to send mail.
Which vulnerabilities affect the service on port 25?→
This database lists 5 CVEs related to SMTP, 5 of them confirmed as exploited by CISA. Examples: CVE-2010-4344, CVE-2010-4345, CVE-2019-16928, CVE-2019-10149.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 25)
- RFC 5321: Simple Mail Transfer Protocol
- RFC 3207: SMTP Service Extension for Secure SMTP over Transport Layer Security
- RFC 8314: Cleartext Considered Obsolete: Use of TLS for Email Submission and Access
- RFC 2505: Anti-Spam Recommendations for SMTP MTAs
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 25 is not guaranteed to be SMTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).